Macatawa Technologies Logo

What the CMMC Phase II Suspension Means For Your Business

If you work with the Department of Defense, you’ve likely heard that the DoD put a major piece of its cybersecurity certification program on hold. The headlines are creating confusion, and understandably so. Words like “suspended” and “paused” can sound like a hall pass. They’re not. Here’s what actually happened, what it means for your business, and what you should do right now.

A Quick Recap: What is CMMC?

CMMC – the Cybersecurity Maturity Model Certification – is the DoD’s framework for ensuring that defense contractors and their partners have real cybersecurity protections in place for sensitive government information. It rolls out in phases, with Phase 2 being the stage that required mandatory third-party audits by an accredited assessor. That phase was set to go into effect on November 10, 2026.

What Just Changed

On July 13, 2026, the DoD announced the immediate suspension of CMMC Phase 2 – along with all future implementation milestones.

There were two compounding problems driving this decision. First, Phase 2 was generating costs and administrative burdens so significant that smaller and mid-sized businesses were being pushed out of the defense supply chain. That’s the opposite of what the program was designed to do. The DoD relies on a broad, competitive supplier base to keep pace with adversaries – shrinking that base in the name of security was seen as a strategic liability.

Second, the DoD’s own CIO put it plainly: there simply weren’t enough accredited auditors to certify the number of companies that needed it before the deadline.

To address this, the DoD launched a CMMC Reform Task Force – a 60-day top-to-bottom review of the entire program. The task force has three priorities:

  1. Cutting compliance costs, especially for small and mid-sized businesses
  2. Making the program more scalable and realistic to implement
  3. Replacing administrative burden with security measures that actually protect data

The task force is expected to deliver its recommendations in Fall 2026, after which a revised CMMC Phase 2 framework will be released.

What This Does NOT Mean

This is the part that matters most – and the part that’s easiest to misread.

The pause applies to the certification process. Your security obligations did not change.

Here is exactly what is still fully active and enforceable:

  • Phase 1 self-assessments are still required. You must complete your annual self-assessment, submit your score to the SPRS database, and file your annual affirmation. Nothing about that has changed.
  • DFARS 252.204-7012 – the contract clause requiring you to protect covered defense information – is still in your contracts. The DoD was explicit: “This action does not eliminate the requirement for companies to protect federal data.” (war.gov official press release, July 13, 2026)
  • NIST SP 800-171 – the technical standard that defines what cybersecurity compliance actually looks like – remains the active benchmark you’re measured against.
  • Government-led spot assessments can still happen. The DoD’s assessment center retains the authority to audit contractors directly – particularly those with unusually high self-assessment scores, those handling sensitive technology, or those flagged by a complaint or whistleblower.
  • The False Claims Act still applies – Submitting an inaccurate self-assessment score is not a paperwork issue – it’s a legal one. The Department of Justice has been actively pursuing cases under its Civil Cyber-Fraud Initiative, and that enforcement posture has not changed.

The bottom line: threat actors targeting the defense supply chain didn’t pause when they read the press release. Your contractual obligations didn’t either.

What You Should Do Right Now

Whether you were actively working toward CMMC certification or just watching the deadline, here’s how to use this window wisely.

Keep Moving on NIST SP 800-171

Phase 1 self-assessments are still live. That means the required cybersecurity controls – multi-factor authentication, access management, incident response, and more – are still mandatory. Don’t let your momentum stall.

Make Sure Your SPRS Score is Accurate

Contracting officers verify your self-assessment score in the SPRS database before awarding contracts. An inflated or outdated score doesn’t just hurt your credibility – it creates real legal exposure under the False Claims Act. If your score doesn’t reflect your current posture, now is the time to fix it.

If You Were Mid-Assessment, Consider Finishing It

If your organization was already working through a third-party assessment, stopping now may cost more than it saves. A verified, well-documented security posture is a genuine competitive differentiator right now – and when the reformed framework drops, companies with that posture already in place will move faster and more confidently than those starting from scratch.

Watch for the Reform Task Force Report

The 60-day review window runs through approximately mid-September 2026. Expect the revised CMMC Phase 2 framework to lean more heavily on self-attestation and commercial security tools, and to be more accessible for smaller businesses. When the report drops, you’ll want to be positioned to act quickly – not scrambling to catch up.

The Bottom Line

The headline says “suspension.” The reality is more nuanced.

For businesses that have already done the work, this is a moment to hold your position. Your investment isn’t wasted – it’s a head start. You have a clean SPRS score, documented security controls, and a defensible posture. That is a competitive advantage right now, and it will be when the new framework launches.

CMMC Phase 2 isn’t going away. It’s being rebuilt to work better. The security obligation underneath it never changed.

Not sure where your business stands? We help defense contractors and their partners meet CMMC Level 1 requirements – from identifying gaps in your current controls to making sure your SPRS score accurately reflects where you stand. Contact us and let’s make sure you’re covered.

Don't forget to share this post!

Topics

Recent Articles

Your Employees Are Using AI, Do You Know What They’re Sharing?

Imagine an employee is drafting a proposal and pastes the client's details into a free AI chatbot to help polish the language. Another is using AI to summarize an internal report. A third is asking it to rewrite HR notes before a performance review.  None of them...

Macatawa Technologies Now Purchasing Apple Devices

We're excited to share a new service update that's going to make getting Apple devices for you team simpler, faster, and more seamless than ever. Macatawa Technologies is now purchasing Apple devices on behalf of our clients. What This Means for You Rather than...

Congress Passes Bill to Protect Small Businesses from Cyberattacks

If you own or manage a small business, cybersecurity may not be the first thing on your mind when you think about what's happening in Washington - but it should be on your radar now. A new cybersecurity bill for small businesses just passed the U.S. House of...

You may also like…

Stay Ahead of the IT Curve

Join our free monthly newsletter for practical cybersecurity tips, tech insights, and local business IT news relevant to your organization.

From the IT team local businesses have relied on since 2002. 
Skip to content